The IAB Tech Lab put two load-bearing pieces of privacy plumbing out for public comment this week: the Global Privacy Platform (GPP) and the Data Deletion Request Framework v2.0. The comment window closes on 11 September 2026 — which gives publishers roughly four weeks to read drafts that will eventually rewrite parts of their consent stack whether they read them or not.
This is not a cosmetic pass. The GPP changes remove the MSPA state-by-state coverage approach, eliminate Service Provider and Opt-Out Option Modes, drop secondary usage consents, and simplify notice and choice fields. On the deletion side, DDRF v2.0 clarifies the JWT definitions for identity and deletion requests and improves result feedback, so that a deletion request produces a clearer, more verifiable answer about what actually happened.
Tech Lab CEO Anthony Katsur frames the intent as making compliance “more consistent, transparent, and practical.” That framing is fair — the US state privacy landscape has produced a consent architecture of genuine baroque complexity, and pruning it is overdue. But “simpler” describes the destination, not the journey. Every one of those removed modes and dropped fields is code that somebody currently runs, and the publishers running it are the ones who inherit the migration.
01Simplification is still a migration
The pattern with consent-standard revisions is consistent: the parts being deleted are always tangled deeper into implementations than anyone remembers. If your consent setup leans on MSPA’s state-by-state coverage, or on Service Provider Mode or Opt-Out Option Mode, those are not isolated toggles in a CMP dashboard. They tend to reach into GAM key-values, Prebid consent handling, vendor contracts that reference specific signal states, and reporting pipelines that segment users by consent mode. Removing them from the standard means every one of those touchpoints needs an audit, and some of them need code.
The DDRF changes are quieter but just as real. Tightened JWT definitions for identity and deletion requests mean the plumbing that receives, authenticates and executes deletion requests gets retested — not merely re-documented. If your deletion workflow was built loosely against the v1 definitions, “clarified” definitions have a way of turning ambiguity you were living with into non-compliance you have to fix.
And there is a calendar problem hiding in the timeline. Comments close 11 September; ratification and vendor rollouts follow. CMP migration work triggered by standards changes has a long history of landing in Q4 — precisely on top of the highest-revenue weeks of the publisher year, when nobody wants an engineer touching the consent string.
02The comment window is the cheap venue
The other half of this story is governance, and it is the half publishers habitually skip. A standards body mid-consultation is the cheapest possible place to get a problem fixed. Filing a comment costs a few hours of a knowledgeable operator’s time. Discovering the same problem after ratification costs an engineering sprint, a vendor escalation, and possibly a compliance gap in the interim. Katsur’s word “practical” only ends up describing the outcome if practitioners — the people who actually run GPP strings through real ad stacks — respond during the window. Historically, comment periods are dominated by vendors and trade lawyers; publisher operational reality is underrepresented, and the standards show it.
03Why this matters for publishers
| Deprecated modes are running in production stacks today | MSPA state-by-state coverage, Service Provider Mode and Opt-Out Option Mode are slated for removal, and implementations that depend on them will need migration work with a real engineering cost. |
|---|---|
| Consent plumbing touches revenue directly | Consent signals gate ad serving, addressability and data use. A botched or rushed migration does not fail quietly — it fails as unfilled impressions, lost addressability, or compliance exposure. |
| The timeline points at Q4 | A September comment close means ratification and CMP rollouts in the following quarters, and transition work has a habit of colliding with the year's best revenue weeks unless publishers force the scheduling conversation early. |
| Deletion requests get a sharper audit trail | Clearer JWT definitions and improved result feedback cut both ways: easier to prove you complied, and harder to hide that you did not. |
04What publishers should do
05The bottom line
Standards work is unglamorous, which is exactly why it keeps catching publishers off guard: the changes are announced in comment windows almost nobody reads and arrive later as vendor emails with deadlines attached. This revision is genuinely aimed at simplification, and the end state will likely be better than the tangle it replaces — but the path between here and there runs through your CMP, your ad server keys and your deletion plumbing. The publishers who read the drafts before 11 September get to shape that path and schedule the work. The ones who do not will do the same work anyway, later, on someone else’s timeline.